Vulnerabilities and security researches forcf7-conditional-fields cf7-conditional-fields
Direction: ascendingJun 07, 2024
Conditional Fields for Contact Form 7 # 0bb038577e135241efdec5ee2901e7ead90280e7
- CVE, Research URL
- Application
- Date
- Nov 14, 2023
- Research Description
- Conditional Fields for Contact Form 7 [cf7-conditional-fields] < 2.4.1 (closed) Conditional Fields for Contact Form 7 <= 2.4.0 - Missing Authorization The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when showing admin notices in all versions up to 2.4.0 (inclusive). This makes it possible for attackers to read admin notices.
- Affected versions
-
max 2.4.1.
- Status
-
vulnerable
Jun 10, 2024
Conditional Fields for Contact Form 7 # CVE-2023-47838
- CVE, Research URL
- Application
- Date
- Dec 09, 2024
- Research Description
- Missing Authorization vulnerability in Jules Colle Conditional Fields for Contact Form 7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Conditional Fields for Contact Form 7: from n/a through 2.4.1.
- Affected versions
-
max 2.4.2.
- Status
-
vulnerable
Jul 20, 2024
Conditional Fields for Contact Form 7 # CVE-2024-5804
- CVE, Research URL
- Application
- Date
- Jul 20, 2024
- Research Description
- The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.13. This is due to missing or incorrect nonce validation on the wpcf7cf_admin_init function. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 2.4.14.
- Status
-
vulnerable
Oct 27, 2024
Conditional Fields for Contact Form 7 # CVE-2024-50412
- CVE, Research URL
- Application
- Date
- Oct 29, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jules Colle Conditional Fields for Contact Form 7 allows Stored XSS.This issue affects Conditional Fields for Contact Form 7: from n/a through 2.4.15.
- Affected versions
-
max 2.5.
- Status
-
vulnerable
May 06, 2026
Conditional Fields for Contact Form 7 # CVE-2026-25863
- CVE, Research URL
- Application
- Date
- May 05, 2026
- Research Description
- Conditional Fields for Contact Form 7 WordPress plugin through version 2.6.7 contains an uncontrolled resource consumption vulnerability in the Wpcf7cfMailParser class where the hide_hidden_mail_fields_regex_callback() method reads an iteration count directly from user-supplied POST parameters without validation or upper bound enforcement. Unauthenticated attackers can supply an arbitrarily large integer value through the REST API endpoint to cause unbounded loop execution with multiple preg_replace() operations, exhausting server memory and crashing the PHP process.
- Affected versions
-
max 2.6.7.
- Status
-
vulnerable